CVE-2022-48197
MEDIUM NUCLEIYui < 2800 - XSS
Title source: ruleDescription
Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, TreeView component and the YUI Javascript library overall are not affected. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by SITE Team · textwebappsphp
https://www.exploit-db.com/exploits/51198
Nuclei Templates (1)
Yahoo User Interface library (YUI2) TreeView v2.8.2 - Cross-Site Scripting
MEDIUMVERIFIEDby ctflearner
Shodan:
html:"bower_components/yui2/" || http.html:"bower_components/yui2/"
FOFA:
body="bower_components/yui2/"
References (6)
Scores
CVSS v3
6.1
EPSS
0.3674
EPSS Percentile
97.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
yui_project/yui
2000 - 2800
Published
Jan 02, 2023
Tracked Since
Feb 18, 2026